Stored Cross-Site Scripting Vulnerability in Events Manager Plugin for WordPress
CVE-2025-12976
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 December 2025
What is CVE-2025-12976?
The Events Manager plugin for WordPress exposes a Stored Cross-Site Scripting vulnerability through the 'events_list_grouped' shortcode. This weakness arises from inadequate input sanitization and output escaping of user-supplied attributes, affecting all versions up to 7.2.2.1. Authenticated users with contributor-level access can exploit this vulnerability to inject arbitrary scripts, which may execute when other users access the compromised pages, putting site security at risk.
Affected Version(s)
Events Manager β Calendar, Bookings, Tickets, and more! * <= 7.2.2.1